A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #2761  by kiskav
 Thu Sep 16, 2010 3:09 am
Does any has idea about the Fakespypro Gang ? Hope, they too will have a big history like Dogma Millions.

Some of the Variants of Fakespypro Noticed till date are - Antivirus system pro, Antivirus solution pro, Antivir solution pro, Security Suite, Antivirus IS ...... This list keeps Going..
Note: i dont remember all other clones of the same. Below is the GUI of one of its variant.

Image

Recently, By sept 11- A huge outbreak occured. Most of the US Users got their pc infected with the rogueware "Security Suite". Does any has idea on how these Creators manage to create a bigger impact..?

I do aware of the Generic answers like, "Crack sites, Social networking sites, Porn sites Spreads this." <------ Apart from this generic answer, does any has a specific track on this gang ?

Note: Sept 16, These creator changed the Rogueware "Security Suite" to "Antivirus IS". If any has the sample of "Antivirus IS", Please share the sample as well.

Thanks & Regards,
Kiskav
 #2763  by EP_X0FF
 Thu Sep 16, 2010 8:40 am
kiskav wrote:Recently, By sept 11- A huge outbreak occured. Most of the US Users got their pc infected with the rogueware "Security Suite". Does any has idea on how these Creators manage to create a bigger impact..?
Adobe Reader/Flash zero days? :)
 #2765  by kiskav
 Fri Sep 17, 2010 1:21 am
Hi Ep,

Thanks for your reply. On what i read & saw, The Adobe exploit dropped the files csrss.exe & sendEmail.dll, Registers it & forwards a link to the contacts owned by the infected user.

I've also seen the same by nullptr sample. So, Adobe Exploit should not be affiliated with this FakeSpypro Outbreak.. Marketing Executives of This infection has the nature of hosting an add in a legitimate site & spreads the dropper through the same.. Not sure, whether they follow the same methodology or something new..

The below snapshot is an appology post from a Legitimate site(Gizmodo) Editor. The very first variant of Fakespypro manged to fool sites & hosted their Malware.

Image

Does any has new news like the one above which speaks about the Techniques followed by the latest variants (Security Suite or Antivirus IS ??
 #2953  by EP_X0FF
 Thu Oct 07, 2010 4:36 am
Desktop Security 2010

http://www.virustotal.com/file-scan/rep ... 1286426148

Runs from C:\Documents and Settings\UserName\Application Data\Desktop Security\

Unpacked size is about 20 Mb.

GUI
Image

Warnings
Image

Payme
Image

Removal is simple.
Attachments
pass: malware
(2.6 MiB) Downloaded 126 times
Last edited by EP_X0FF on Sat Apr 16, 2011 6:26 am, edited 1 time in total. Reason: Screenshots has been resized to be more accurate
 #3227  by PX5
 Tue Oct 26, 2010 1:29 pm
Maybe one of the mods can sort where this belongs, it will do something very similar to this...

http://www.threatexpert.com/report.aspx ... 67b997acac

Which has my pal Sirefef in the package, I dont think the fake crap is all that new but this should be a newish version of Sirefef atleast.

No testing done yet, so no idea if there is anything to toot a horn about, will be interested to see.

http://www.virustotal.com/file-scan/rep ... 1288065542

VT appears to be getting hammered, so unable to fresh scan the dropper.
Attachments
(172.54 KiB) Downloaded 95 times
 #3241  by wealllbe20
 Wed Oct 27, 2010 2:32 pm
ThinkPoint

Another Fake AV.

Installed via a java exploit on java version 1.5.18

disables taskmanager

Had to actually go into settings in the fake av program and disable autostart virus scanner

Then was able to goto start->run->type in command

and from command prompt told user to run: taskkill /im hotfix.exe /f

Afterwards was able to run taskmanager


Also created which appeared to be a random named batch file on the desktop and mstsc.exe on the desktop(same pe name as remote desktop)

if batch script was to run it would run the mstsc file and delete it and then delete batch script itself.


http://www.virustotal.com/file-scan/rep ... 288188708# 8/14
Attachments
pass "infected"
(490.63 KiB) Downloaded 121 times
Last edited by EP_X0FF on Sat Apr 16, 2011 8:10 am, edited 1 time in total. Reason: Title edited
 #3242  by EP_X0FF
 Wed Oct 27, 2010 4:53 pm
wealllbe20 wrote:Another Fake AV.
That's the same MSE-alike fake av ThinkPoint. Written on Delphi + UPX.

This build was kinda buggy on my machine - it was unable write itself correctly in registry and died after reboot.

http://www.kernelmode.info/forum/viewto ... 3186#p3186
 #3285  by EP_X0FF
 Tue Nov 02, 2010 4:41 pm
AV Defender 2011

Written on Delphi, passed through cryptor.

Copies itself (XP) to Documents and Settings\UserName\Application Data\RandomName\RandomName.exe

Annoying pop-ups, tons of fake detections included.

http://www.virustotal.com/file-scan/rep ... 1288715752

Autostart through HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell registry key.

GUI

Image
Image
Attachments
pass: malware
(937.46 KiB) Downloaded 119 times
Last edited by EP_X0FF on Sat Apr 16, 2011 6:28 am, edited 1 time in total. Reason: Screenshots has been resized to be more accurate
  • 1
  • 4
  • 5
  • 6
  • 7
  • 8